Tendermint is a blockchain consensus engine and Byzantine fault-tolerant framework used in cryptocurrency and distributed-ledger systems, with a narrow product focus centered on its core consensus implementation. The vulnerability profile reflects the engine's role in cryptographic state machines, with recurrent weakness classes including uncontrolled resource consumption, improper cryptographic-signature verification, excessive memory allocation, and out-of-bounds writes that touch on both protocol validation and memory-safety concerns. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tendermint over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25072HIGH Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of sy | Dec 27, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-15091MEDIUM TenderMint from version 0.33.0 and before version 0.33.6 allows block proposers to include signatures for the wrong block. This may happen naturally if you start a network, have it | Jul 2, 2020 | 6.5 | 22 | NO | NO |
CVE-2021-21271MEDIUM Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - written in any programming language - and securely replicates it | Jan 26, 2021 | 6.5 | 21 | NO | NO |
Tendermint before versions 0.33.3, 0.32.10, and 0.31.12 has a denial-of-service vulnerability. Tendermint does not limit the number of P2P connection requests. For each p2p connect | Apr 10, 2020 | 3.7 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tendermint.
Media articles that mention a CVE ID that affects a product developed by Tendermint — matched by CVE ID, not by vendor name.